Im In Your Leenucks Box Changing Your Password
ID: 96d09343-0d1e-5d45-a640-e7a90f80b48d
STIX ID: report--96d09343-0d1e-5d45-a640-e7a90f80b48d
Feed Name: Darknet
**Executive Summary:** DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome/Edge/Brave via an App-Bound Encryption bypass using headless Chromium + IElevator COM and DLL injection; Opera/Opera GX/Vivaldi via DPAPI; Firefox via NSS decryption), includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is distributed as a compiled Windows executable intended for red-team assumed-breach scenarios but represents a high-risk capability if used maliciously.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
